From directive to board plan: decisions you can approve
Turning NIS2 and CRA into something a board can understand, approve and fund: gap assessment, costed roadmap, reporting.

European directives are written for lawyers, not for the people who must decide how to allocate a budget. The gap between the text of NIS2 or the CRA and a decision a board can approve is wide, and closing it is precisely the work that separates a useful compliance project from a stack of documents no one will use.
The problem is not technical. It is one of translation: bringing regulatory obligations, actual risk and budget constraints onto a single readable plan, where every item has a rationale, a cost and a priority. Here is how I approach it.
First: a gap assessment that tells the truth
Everything starts from an honest snapshot of the current state against the applicable obligations — Article 21 of NIS2, Annex I of the CRA — and against real risk. The temptation at this stage is self-indulgence: declaring yourself compliant where you are only partly covered. A gap assessment that overstates maturity is worse than useless, because it produces a false sense of security and a plan calibrated to the wrong problems. Every gap must be documented with evidence, not opinion.
Second: prioritise by risk, not by ease
A gap assessment always surfaces dozens of gaps. Tackling them in order of ease — quick wins first — is the most common and most expensive mistake, because it burns budget on low-impact work and leaves the risks that matter uncovered. Correct priority comes from the intersection of likelihood and impact: which gaps expose you to plausible, severe scenarios? Which touch essential functions? Which are required by law as a precondition? The result is a defensible sequence, where the order of the work can be explained in a sentence.
Third: the roadmap must have numbers
A plan without costs is not a plan: it is a wish list. Every item on the roadmap must carry a cost estimate (people, technology, external services), a realistic timeline and the risk it reduces. This turns the conversation with leadership from “we need more security” — an unmanageable statement — into “with this spend we reduce this exposure by this date”. It is the only form in which a board can actually decide: approve, defer, or knowingly accept the risk.
Residual risk must also be made explicit. No roadmap takes exposure to zero, and pretending otherwise undermines the credibility of the whole plan. Stating clearly what remains uncovered, and why that choice is reasonable, is what distinguishes an adviser from a salesperson.
A useful device is to separate, within the same roadmap, what is needed to be compliant from what is needed to be secure: often they coincide, but not always. Some items are required by law even though their contribution to risk is modest; others cut exposure sharply while not being explicitly mandated. Making this distinction visible lets leadership decide with clarity, instead of treating every line as an undifferentiated, equally urgent obligation.
Fourth: reporting the board can use
Under NIS2 and DORA, management bodies approve and oversee: they therefore need recurring information, not a single opening document. But a board does not read logs or technical dashboards. It needs a few metrics that stay stable over time: roadmap progress against plan, how exposure on the main risks is evolving, the status of significant incidents, and areas where residual risk exceeds the defined tolerance. A few lines, always the same, that convey a direction.
The value of such reporting is not cosmetic. It makes leadership accountability genuinely exercisable: a board that receives this information can show it has overseen, and can decide with full knowledge. That is exactly what the law asks of it.
The role of the adviser
The hard part is not producing the documents, but holding together three languages — the legal language of the norm, the technical language of risk, and the economic language of the decision — without betraying any of them. It is work of synthesis and intellectual honesty, where the recurring temptation is to please: overstate the compliance achieved, or inflate the risks to justify the spend. Both drifts cost the board’s trust, and trust is the only currency in which a security plan gets funded.
The takeaway
A directive becomes action only when someone translates it into decisions you can approve: gaps measured with evidence, priorities set by risk, work with a cost and a date, reporting leadership can actually use. It is unglamorous work, but it is what separates compliance on paper from security that holds.



